Multiple incident reports show attackers repeatedly using exposed or weakly protected Remote Desktop Protocol (RDP) as both an entry point and an internal movement channel. In one intrusion, an actor brute-forced a local administrator account over RDP, created additional access, used Mimikatz to dump credentials and Kerberos tickets, and moved across systems before deploying an XMRig-based Monero miner. Separate reporting on Conti and other hands-on-keyboard operations shows similar post-compromise tradecraft, including credential theft, reconnaissance, use of remote management utilities, and abuse of legitimate Windows administration features to avoid dropping obvious backdoors.
Ransomware and espionage cases show the same pattern extending to interactive remote-control tooling beyond standard RDP. ASEC reported Crysis/Dharma and Venus ransomware actors brute-forcing RDP, stealing credentials, terminating processes, deleting shadow copies, and encrypting systems, sometimes retrying with a second ransomware family after a failed first attempt. North Korea-linked Kimsuky has also used RDP Wrapper, patched Terminal Services, VNC, Chrome Remote Desktop, Ngrok, and malware such as AppleSeed, Amadey, and RftRAT to maintain GUI-based access, evade user awareness, and support keylogging, file theft, and persistent control of compromised hosts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
28 events from the most recent confirmed update back to the earliest known activity.
The LNK-based infection chains unpacked script malware that installed remote-access tools including XRat, Amadey, and RftRAT after compromise.
ASEC reported that in 2023 Kimsuky increasingly used malicious LNK shortcut files, rather than HWP or Office documents, for initial access against targets.
ASEC reports that AppleSeed has been observed since around 2019 as a recurring backdoor used by Kimsuky to install additional malware and remote-access tooling.
ASEC says TinyNuke source code was revealed in 2017, which enabled broader reuse of its capabilities by other attackers.
The ASEC report states that TinyNuke, later used by Kimsuky for HVNC access, was originally discovered as banking malware in 2016.
After gaining control of systems, Kimsuky used RDP or installed Chrome Remote Desktop to exfiltrate information and maintain remote access.
ASEC says recent Kimsuky variants of Amadey and RftRAT were created with or wrapped by AutoIt to hinder analysis and evade security products.
The attackers downloaded chromeremotedesktophost.msi and a batch script that ran remoting_start_host.exe with an attacker-generated authorization code and the PIN 230625.
ASEC says AppleSeed was used to deploy additional tooling including a browser credential stealer, an x64 RDP patcher for multiple sessions, and Ngrok for exposing systems behind NAT.
In the observed campaign, spear-phishing attachments disguised as Hangul, Office, or CHM files launched WSF or JS droppers that decoded and executed the AppleSeed backdoor.
ASEC reported that Kimsuky recently began abusing Chrome Remote Desktop to maintain browser-based graphical access to compromised systems.
ASEC says the ransomware operator installed Mimikatz and multiple NirSoft utilities for credential theft and reconnaissance, then used collected credentials and RDP to move to other internal systems.
In previously identified attacks, the actor first attempted to encrypt systems with Crysis and, when that failed, retried encryption using Venus.
According to ASEC, the actor used brute-force or dictionary attacks against weak RDP credentials, then logged in and installed both Crysis and Venus ransomware on victim systems.
ASEC discovered that a threat actor associated with Crysis ransomware was also deploying Venus ransomware in attacks that started through externally exposed RDP services.
The same report says Conti operators dump LSASS, use Mimikatz and other credential tools, spread with SMB admin shares and BITSAdmin, leverage AnyDesk and Atera, and may exfiltrate files to Mega.
Trend Micro reported that Conti intrusions can begin with phishing emails delivering BazarLoader or exploitation of public-facing firewalls using CVE-2018-13379 and CVE-2018-13374.
ASEC also observed Kimsuky distributing a customized tvnserver that supports reverse VNC without installing a service, enabling control from a C2-hosted viewer.
In the observed activity, Kimsuky enabled only TinyNuke's hidden VNC capability, allowing graphical control of infected systems without the user seeing the attacker session.
ASEC reported that Kimsuky used its AppleSeed backdoor to install VNC-based remote-control malware, including TinyNuke HVNC and a customized TightVNC implementation, on compromised systems.
About an hour into the intrusion, the actor deployed an XMRig-based Monero miner via svshost.exe, hid related files, and attempted outbound connections to known mining endpoints before disconnecting.
After access, the actor logged in from additional IPs, moved laterally over RDP to multiple systems including a domain controller, and used Mimikatz to dump credentials and export Kerberos tickets.
An account used in the intrusion was created the previous day from source IP 54.38.67.132, according to the DFIR Report.
The DFIR Report describes an intrusion in which an attacker brute-forced a local administrator password over RDP to gain initial access to the environment.
The ransomware payload 1pgp.exe was executed, encrypted the system, and left a ransom note; the sample was linked to Dharma/Crysis through a PDB path in the binary.
During the intrusion, the attacker ran shadow.bat and LogDelete.bat, terminated applications with closeapps.bat, and placed 1pgp.exe in Startup folders and a Run key for persistence.
At 09:36 UTC in the same intrusion, the attacker executed NS.exe from the desktop to scan and map file shares before ransomware deployment.
In the DFIR Report case, a ransomware operator linked to Dharma/Crysis logged in from IP 217.138.202.116 as a local administrator at 08:58 UTC.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
asec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourcetrendmicro.com
Open sourcethedfirreport.com
Open sourceasec.ahnlab.com
Open sourcethedfirreport.com
Open sourcethedfirreport.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.